Connecting Live SIM Cards to a Private Test Network via Roaming Authentication

NOFFZ BSE with eSim

BASE STATION EMULATOR

Connecting Live SIM Cards to a Private Test Network
via Roaming Authentication

Cellular testing of automotive modules and connected devices traditionally depends on dedicated test SIM cards or specially provisioned eSIM profiles. This approach has long been the industry standard — and it remains the most straightforward path. However, a newly validated pilot project now demonstrates an alternative: enabling a live, commercially provisioned SIM card to authenticate against and register on a private NOFFZ BSE test network, without routing any actual data traffic through the public network operator’s infrastructure.

This article explains the architecture behind this capability, the role of the Diameter Edge Agent (DEA) and Home Subscriber Server (HSS), and what is required from automotive OEMs and their network operators to make it a reality.

 

NOFFZ BSE with eSim 2

The following diagram illustrates how a live network SIM authenticates against the operator’s HSS while attaching to the NOFFZ BSE as a visited network.

 

The Traditional Constraint: Why Test SIMs Are Required

Authentication in cellular networks relies on cryptographic secret keys stored in both the SIM card and the operator’s HSS. These keys are never shared with third parties — including test equipment manufacturers. Because the NOFFZ BSE cannot access these keys, it cannot replicate the authentication process for commercial SIM cards on its own.

As a result, cellular testing has historically required either a physical test SIM card programmed with known credentials, or an eSIM profile specifically provisioned for the test environment. Both methods are well understood and remain fully supported. The pilot described below does not replace them — it opens an additional option.

The Pilot: Live SIM Registration on the BSE Test Network

NOFFZ BSE has successfully demonstrated — in a working office prototype — that a SIM card issued by a nationwide network provider can register on the BSE test network. In this configuration, the device under test (for example, a connectivity module with an eSIM provisioned in the operator’s HSS) attaches to the BSE network as if it were a roaming partner.

The key architectural insight is the separation of the user-plane and the control-plane:

Real network traffic stays entirely local to the BSE test network. Only the authentication signalling is routed to the network operator’s HSS servers. This means the operator’s production infrastructure carries no subscriber data from the test environment — merely the cryptographic challenge-response exchange needed to verify the SIM’s identity.

From the device’s perspective, it successfully attaches to a cellular network using its original, commercially issued SIM or eSIM — with no changes to the card’s profile.

How It Works: DEA and HSS Integration

The integration relies on two key network elements:

Diameter Edge Agent (DEA). The DEA acts as an encrypted gateway between the BSE test network and the network operator’s HSS. All authentication signalling — specifically the Diameter-based Authentication and Key Agreement (AKA) messages — passes through the DEA. Critically, the DEA encrypts the signalling channel, which means the BSE has no ability to intercept or decode the secret authentication keys. Subscriber privacy and operator security are preserved by design.

Home Subscriber Server (HSS). The HSS is the operator’s subscriber database — the authoritative store for each SIM’s authentication credentials. When a device attempts to attach to the BSE network, the BSE forwards the authentication request via the DEA to the operator’s HSS. The HSS validates the SIM and returns the appropriate authentication vectors. The BSE acts as a visited network, and the operator’s HSS acts as the home network — a standard roaming model.

This architecture is well-established in cellular roaming. What is novel here is applying it to a controlled test environment, enabling the BSE to function as a trusted visited network for live operator SIM cards.

What OEMs Need to Enable This Capability

The technical architecture is proven. The primary remaining dependency is the relationship between the automotive OEM and its network operator. Three conditions must be met:

  1. Operator agreement. The network operator must agree to open a DEA connection to the BSE infrastructure. This requires the operator’s technical and commercial cooperation — they must be willing to treat the BSE as a roaming partner for the OEM’s devices.
  2. HSS access permission. The operator must grant permission for authentication queries from the BSE to reach its HSS. This is the core concession — without HSS access, the live SIM cannot be authenticated on the test network.
  3. OEM leverage. In practice, this means the OEM (such as a major automotive manufacturer) must exercise its commercial relationship with the operator to secure access. Operators are not obligated to provide this connection by default; it requires negotiation and contractual agreement.

Once these conditions are satisfied, the technical integration is straightforward. NOFFZ BSE has the expertise and the proven prototype to complete the connection rapidly.

Practical Implications for Automotive Testing

For devices returned from the field — such as connectivity modules already provisioned with a production eSIM profile — this capability eliminates the need to re-provision the eSIM with a test profile before testing. The module can be connected to the BSE test network using its existing, live credentials.

This has significant benefits for failure analysis and regression testing of field-returned units, where altering the SIM state before testing could mask the original defect or complicate the diagnostic process.

The same model can support testing of devices prior to field deployment, provided the eSIM profile has already been provisioned in the operator’s HSS — as would be the case for any commercially activated device.

Conclusion

The pilot conducted with a nationwide network provider demonstrates that live SIM authentication on the NOFFZ BSE test network is technically feasible and already working. The architecture — using a DEA to route encrypted authentication signalling to the operator’s HSS while keeping all data traffic local — is sound, secure, and consistent with standard cellular roaming practices.

Realising this capability at scale requires OEMs to engage their network operators and negotiate HSS access. For OEMs with the leverage to do so, the result is a powerful extension of the BSE test environment: the ability to test connected devices using their original, production SIM credentials — with no changes to the device or its subscription.

 

Learn more about the NOFFZ Base Station Emulator and how it enables advanced LTE/5G test scenarios.